Privacy Policy

Last updated: May 12, 2026

1. Introduction

Welcome to RedGifs AI. This Privacy Policy is designed to help you understand how ERS Interactive ("RedGifs AI," "we," "our," or "us") collects, uses, and safeguards the information you provide to us through our website, mobile application, and other digital services (collectively, the "Services").

By accessing or using our Services, you agree to the practices described in this Privacy Policy. If you do not agree with this Policy, please do not access or use our Services.

ERS Interactive is the data controller responsible for your personal data. We are committed to protecting your privacy and complying with applicable data protection laws.

2. Information We Collect

2.1 Information You Provide Directly

We collect information you provide directly to us when you use our Services. This may include:

  • Account information (e.g., username, email address)
  • Profile information
  • Content you create, share, or post on our Services
  • Communications you send to us
  • Survey responses

2.2 Information We Collect Automatically

When you access or use our Services, we may automatically collect certain information, including:

  • Device information (e.g., device type, operating system)
  • Log data (e.g., IP address, access times)
  • Usage data (e.g., features used, content viewed)
  • Location data (with your permission)

2.3 Information from Other Sources

We may receive information about you from other sources, including:

  • Other users of our Services
  • Social media platforms, if you connect your account to our Services
  • Third-party services that you use to log into our Services

2.4 Legal Basis for Processing (for EU Users)

For users in the European Union, we process your personal data based on one or more of the following legal grounds:

  • Your consent
  • Performance of a contract with you
  • Compliance with a legal obligation
  • Our legitimate interests, provided they do not override your fundamental rights and freedoms

3. How We Use the Information We Collect

We use the information we collect for various purposes, including:

  • Providing, maintaining, and improving our Services
  • Personalizing your experience
  • Communicating with you about our Services
  • Analyzing usage patterns and trends
  • Detecting and preventing fraud and abuse
  • Complying with legal obligations

We may also use aggregated or de-identified data for any purpose, which is not subject to restrictions under this Privacy Policy.

For EU users, we process your data for these purposes based on the legal grounds outlined in Section 2.4.

4. When We Disclose the Information We Collect

We may share your information in the following circumstances:

4.1 With Affiliates

We may share information with our affiliated companies for purposes consistent with this Privacy Policy.

4.2 With Service Providers

We may share information with third-party vendors, consultants, and other service providers who need access to such information to carry out work on our behalf.

4.3 For Legal Reasons

We may share information if we believe it's necessary to comply with applicable laws, regulations, legal processes, or governmental requests.

4.4 In Connection with Business Transfers

If we're involved in a merger, acquisition, financing, or sale of business assets, we may transfer your information as part of that transaction.

4.5 With Your Consent

We may share information for any other purposes disclosed to you at the time we collect the information or pursuant to your consent.

4.6 User Content and Public Features

Some features of our Services may allow you to share information publicly. Any information you submit through such features will be publicly available.

4.7 International Data Transfers

Your information may be transferred to, and processed in, countries other than the country you live in. These countries may have data protection laws different from the laws of your country. We implement appropriate safeguards to protect your information when transferred internationally.

5. Cookie Policy

5.1 What are Cookies?

Cookies are small data files stored on your device when you visit a website. They are widely used to make websites work more efficiently and provide information to the owners of the site.

5.2 Types of Cookies We Use

We use the following types of cookies:

  • Essential Cookies — necessary for the website to function properly.
  • Functional Cookies — remember your preferences and enhance your experience.
  • Analytics Cookies — help us understand how visitors interact with our website.
  • Advertising Cookies — used to deliver relevant ads and track ad campaign performance.

5.3 How We Use Cookies

We use cookies to:

  • Keep you signed in
  • Remember your preferences
  • Understand how you use our Services
  • Improve our Services
  • Deliver relevant advertising

5.4 Third-Party Cookies

Some cookies may be placed by third parties when you use our Services. These third parties may collect your information for their own purposes.

5.5 Managing Cookies

Most web browsers allow you to control cookies through their settings. However, if you limit the ability of websites to set cookies, you may worsen your overall user experience.

5.6 Do Not Track

Some browsers have a "Do Not Track" feature that lets you tell websites that you do not want to have your online activities tracked. We currently do not respond to "Do Not Track" signals.

6. Online Analytics and Advertising

6.1 Analytics Services

We use analytics services to help us understand how users engage with our Services. These services may use cookies and similar technologies to collect information about your use of the Services and other websites.

6.2 Advertising

We may work with third-party advertising companies to serve ads when you visit or use our Services. These companies may use information about your visits to our website and other websites to provide relevant advertisements about goods and services that may interest you.

6.3 Your Choices

You can opt out of certain advertising features through your device settings, ad network preferences, or our Services settings. For more information about opting out of interest-based advertising, visit www.aboutads.info/choices or www.youronlinechoices.eu.

7. User Choices and Rights

7.1 Account Information

You can update, correct, or delete your account information at any time from your account settings. If you need assistance, please contact us at legal@thepeach.ai

7.2 Communication Preferences

You can opt out of receiving promotional communications from us by following the instructions in those communications. If you opt out, we may still send you non-promotional communications, such as those about your account or our ongoing business relations.

7.3 Cookie Preferences

You can manage your cookie preferences through your browser settings. Please note that disabling certain cookies may impact the functionality of our Services.

7.4 Data Subject Rights

Depending on your location, you may have certain rights regarding your personal information, including:

  • The right to access your personal information
  • The right to rectify inaccurate personal information
  • The right to request the deletion of your personal information
  • The right to restrict the processing of your personal information
  • The right to data portability. You can self-serve a machine-readable export of your account data at any time from your account settings (subject to a once-per-day limit), or by contacting us at the address in section 7.6.
  • The right to object to the processing of your personal information

You can adjust which categories of email you receive in your settings, unsubscribe from all non-essential email, or delete your account — at which point we also cancel any email already queued to you.

7.5 Additional Rights for EU Users

If you are located in the European Union, you have additional rights under the General Data Protection Regulation (GDPR), including:

  • The right to withdraw consent at any time
  • The right to lodge a complaint with a supervisory authority

7.6 Exercising Your Rights

To exercise any of these rights, please contact us at legal@thepeach.ai We will respond to your request in accordance with applicable data protection laws.

8. Children's Privacy

8.1 Age Restrictions

Our Services are intended for adults 18 years of age or older. We do not knowingly collect personal information from anyone under 18.

8.2 Handling of Underage Users' Data

If we learn that we have collected personal information from a person under 18, we will take steps to delete that information as quickly as possible. If you believe that we might have any information from or about a person under 18, please contact us at legal@thepeach.ai

9. Security Measures

We take reasonable measures to help protect information about you from loss, theft, misuse and unauthorized access, disclosure, alteration and destruction. However, no internet or electronic communications service is ever completely secure or error-free.

9.1 Data Protection Measures

We implement various security measures to maintain the safety of your personal information when you use our Services, including:

  • Encryption of sensitive information
  • Regular security audits
  • Access controls to limit employee access to personal information
  • Secure data storage practices

9.2 User Responsibilities

While we strive to protect your personal information, the security of your data also depends on you. We urge you to take steps to keep your personal information safe, such as choosing a strong password and keeping it private, as well as logging out of your account after using shared computers.

9.3 Data Breach Notification

In the event of a data breach that affects your personal information, we will notify you and the relevant authorities as required by applicable laws.

10. Data Retention

10.1 How long we keep your data

When you delete your account through the in-app "Delete account" control or by emailing legal@thepeach.ai, we run a two-step erasure flow:

  • Immediately: we scrub the personal-identifier columns on your user record (email, handle, display name, bio, avatar), revoke every active session, cancel and delete your upstream payments customer record, retire every companion you own, hard-delete your direct-message conversations together with the messages in them, erase your email-category preferences, and cancel any transactional email already queued or scheduled to you that has not yet been sent.
  • After a 30-day grace window: we hard-delete your authentication credentials, your draft companion creation work, and orphaned media binaries. The grace window exists so a deletion requested by mistake — or by an account takeover — can be reversed by re-authenticating; once it elapses, the deletion is irreversible.

10.2 What survives the deletion

Some content is retained in anonymized form because removing it would distort other users' experience:

  • Public-room messages you sent are deleted with your account; the rest of the conversation thread continues without your lines.
  • Comments and reactions you made on public posts authored by other users remain attached to the post but are reattributed to a generic "deleted user" placeholder. Other users' ability to read the post is preserved; your identity is not.
  • Audit and security event logs are retained for the period required to investigate fraud, abuse, and security incidents, and to satisfy our legal and regulatory recordkeeping duties. These logs reference the system-generated user identifier and a record of which categories of transactional email we sent you (by date and email type — never the message contents). Personal identifiers are scrubbed at deletion; the category-level send record is retained for the legal and regulatory recordkeeping period.

10.3 No deactivation-without-delete

We do not offer a separate "deactivate" or "pause" option that retains your data without active use. The only ways your data leaves the active system are: (a) you delete your account, or (b) we delete it for cause (terms violation, court order, regulatory direction). In either case the same two-step erasure flow runs.

10.4 Backups

Encrypted database backups are retained for operational disaster recovery on a rolling window not exceeding 35 days. Restored copies of your data, if any, are re-subjected to the deletion you previously requested when the backup is rehydrated; we do not re-create deleted accounts from backup absent a documented incident response.

11. International Data Transfers

11.1 Where your data is processed

We currently operate the Services from a single Google Cloud Platform region: us-central1 (Iowa, United States). Application servers, primary database, and object storage all reside in that region. We do not currently replicate to additional regions.

11.2 Transfers from the EEA / UK

If you access the Services from the European Economic Area, the United Kingdom, or Switzerland, your personal information is transferred to and processed in the United States. We rely on the data subject's informed consent (Article 49(1)(a) GDPR) at registration as the lawful basis for that transfer; the "I confirm I am 18 or older" checkpoint discloses the cross-border processing context.

11.3 Future regions

When we begin processing personal information in additional regions or under additional transfer mechanisms (for example, the EU-US Data Privacy Framework or Standard Contractual Clauses), we will update this section before traffic begins flowing and provide a meaningful notice through the "Notification of Changes" mechanism in §13.

11.4 Further information

For questions about the specific safeguards in place for your transfer, contact us at legal@thepeach.ai

12. Sub-Processors

We rely on the third-party providers listed below to operate the Services. Each row identifies the data we send, the purpose, and our deletion contract — what happens to the data at the provider when you delete your account or we cease using the provider.

12.1 Provider list

  • Google Cloud Platform (Cloud SQL for PostgreSQL, Google Cloud Storage, Google Kubernetes Engine, Cloud Build) — hosts the application database, uploaded and generated media binaries, and the application runtime. Region: us-central1. Deletion contract: account deletion removes your rows from the database and clears references to your media; orphaned objects in Cloud Storage are reaped by a daily lifecycle sweep, with the storage bucket's own 35-day lifecycle rule as the backstop. This 35-day bucket-lifecycle window is separate from the 30-day account-deletion grace window described in §10.
  • Stripe, Inc. — processes subscription payments and stores the payment-method tokens linked to your account. Data sent: account identifier, billing email, subscription status, payment method tokens. Deletion contract: account deletion calls Stripe's subscription cancel API for every active subscription and the customer-delete API for the upstream record; Stripe retains the resulting transaction history per its own legal-and-tax-compliance retention schedule, which we cannot override.
  • Anthropic, PBC (Claude API) — processes conversational prompts and character generation requests when configured as the language-model backend. Data sent: prompt text, recent conversation context, generation parameters. Deletion contract: per Anthropic's API terms, prompts are not used to train models; ephemeral inference logs are retained on Anthropic's side per their published policy. We do not send your account email or other direct identifiers.
  • Self-hosted vLLM cluster (when configured) — alternative language-model backend operated under our own control in us-central1. Data sent: same as above. Deletion contract: the cluster does not persist prompts beyond the request lifetime.
  • Image generation providers (Seedream, NanoBanana, Veo) — generate companion avatars and other imagery. Data sent: text prompts derived from your character descriptions; no account identifiers. Deletion contract: prompt-derived generated assets we receive back are stored in our Google Cloud Storage bucket and are subject to the deletion flow above. Provider-side retention of the prompt text itself follows each vendor's policy and we do not control it.
  • Email transactional relay (operated in-cluster by us) — sends verification codes, password recovery, and account-state notifications. Data sent: destination email address, message body, delivery status. Deletion contract: account deletion removes your email from the customer-app database, so no further outbound mail is queued; bounce-and-suppression metadata may persist on the relay until cleared by an operator-initiated purge. The address held in suppression metadata is the same address you provided; no other personal information is retained there.
  • BytePlus (media asset library, ap-southeast-1) — an offshore media-asset processor in Southeast Asia that stores generated companion avatar and media assets. Data sent: companion-derived asset references and generated media asset-group identifiers only; we do not send your account email, handle, or other direct identifiers. International transfer: assets are stored in the ap-southeast-1 region. Deletion contract: account deletion deletes the associated asset groups on BytePlus (idempotent on a remote not-found), driven by the same anonymization flow above and a bounded retry job.

12.2 Adding a sub-processor

We will update this list before sending personal information to any new sub-processor. Material additions are announced through the §13 notification mechanism.

12.3 Links to other sites

The Services may contain links to third-party websites that are not sub-processors and do not receive your personal information from us. We are not responsible for those sites' privacy practices and encourage you to review their policies before providing them with personal information.

13. Changes to the Privacy Policy and Cookie Policy

13.1 Policy Updates

We may update this Privacy Policy and Cookie Policy from time to time. The updated version will be indicated by an updated "Last Updated" date and the updated version will be effective as soon as it is accessible.

13.2 Notification of Changes

If we make material changes to this Privacy Policy, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Policy frequently to be informed of how we are protecting your information.

13.3 Continued Use of Services

Your continued use of our Services after the effective date of any change to the Privacy Policy will constitute your acceptance of the amended Privacy Policy. If you do not agree to the revised policy, please discontinue using our Services.

14. Contact Information

If you have any questions about this Privacy Policy or our privacy practices, please contact us at:

We operate virtually and do not maintain a physical office address.

For users in the European Union:

15. Regional Privacy Disclosures

15.1 California Residents

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA). These rights include:

  • The right to know what personal information we collect about you and how we use and disclose it
  • The right to request deletion of your personal information
  • The right to opt-out of the sale of your personal information
  • The right to non-discrimination for exercising your CCPA rights

To exercise your CCPA rights, please contact us at legal@thepeach.ai

15.2 European Economic Area (EEA) and United Kingdom Residents

If you are located in the EEA or UK, you have certain rights under the GDPR and UK GDPR, respectively. These include:

  • The right to be informed about our processing of your personal data
  • The right to access and receive a copy of your personal data
  • The right to rectification of any inaccurate personal data
  • The right to erasure of your personal data in certain circumstances
  • The right to restrict processing of your personal data
  • The right to data portability
  • The right to object to processing based on legitimate interests
  • Rights related to automated decision-making and profiling

To exercise these rights, please contact us at legal@thepeach.ai

15.3 Nevada Residents

Nevada residents have the right to opt out of the sale of certain "covered information" collected by operators of websites or online services. We currently do not sell covered information, as "sell" is defined by Nevada law, and we don't have plans to do so in the future.

15.4 GDPR Compliance

For users in the European Union, we comply with the GDPR. This includes:

  • Processing personal data lawfully, fairly, and transparently
  • Collecting personal data only for specified, explicit, and legitimate purposes
  • Ensuring personal data is adequate, relevant, and limited to what is necessary
  • Keeping personal data accurate and up to date
  • Storing personal data only as long as necessary
  • Processing personal data in a manner that ensures appropriate security

If you have any questions about our GDPR compliance, please contact us at legal@thepeach.ai

Appendix R — Adult Surface (redgifs.thepeach.ai) Privacy Addendum

This appendix supplements the global Privacy Policy above for users accessing the Services through the adult (NSFW) surface operated by ERS Interactive. In the event of a conflict between the global policy and this appendix, the appendix controls for users on this surface. The effective date of this appendix matches the global policy date: May 12, 2026.

R.1 Age-attestation gate disclosure. Access to the Services on this surface requires that you affirmatively confirm at registration that you are at least 18 years old (or the age of legal majority in your jurisdiction, if higher). This is a self-attestation: we record that you affirmed it and the timestamp of that affirmation. We do NOT collect a government-issued identification document, a selfie or any biometric or liveness signal, or your date of birth, and we do NOT route any identity materials to a third-party identity-verification provider. Should a stronger age-verification mechanism be required by the law of your jurisdiction, ERS Interactive will disclose it here and in the sub-processor list of the global policy before it takes effect.

R.2 Adult-content data processing. Prompts, conversations, and generated imagery on this surface may contain sexually explicit material. Such content is treated as special-category personal data where local law so requires (notably: GDPR Article 9 categories where they apply). We process this data on the basis of your explicit consent given at registration; you may withdraw consent at any time by deleting your account, which triggers the two-step erasure flow described in the global policy §10. We do not share explicit conversation content with third parties for advertising or analytics purposes; sub-processor disclosures in the global policy §12 govern all other sharing.

R.3 18 U.S.C. § 2257 records custodian. To the extent records-keeping obligations under 18 U.S.C. § 2257 and 28 C.F.R. Part 75 apply to imagery generated, hosted, or made available through the Services on this surface, ERS Interactive is the designated records custodian. Custodian contact: legal@thepeach.ai. The Services do not depict real human performers; AI-generated imagery is produced from text prompts and provider models, and we maintain records sufficient to demonstrate the non-human, AI-generated provenance of material produced through the Services. A formal 2257 statement, including the physical custodian address required by the regulation, will be posted in connection with any production launch and supersedes this placeholder.

R.4 State-specific addenda. Certain US states have enacted age-verification statutes applicable to adult-content websites (including but not limited to Texas, Louisiana, Utah, Virginia, Mississippi, Arkansas, Montana, North Carolina, and Tennessee). The age gate currently operated on this surface is the self-attestation described in R.1. Where a statute applicable to your jurisdiction requires a stronger age-verification mechanism than self-attestation, ERS Interactive will either implement a compliant mechanism — disclosed here before it takes effect — or withhold the Services from that jurisdiction rather than operate in violation of the statute. This appendix is a pre-launch placeholder pending review by external counsel. Contact legal@thepeach.ai with questions specific to your state of residence.